Database/Control plane, storage & DevOps
Pure Storage FlashBlade management interface authentication: MULTI-TENANT ISOLATION: an attacker authenticates to the
Impact
MULTI-TENANT ISOLATION: an attacker authenticates to the FlashBlade management interface as a local account through a path that was never meant to accept logins, and lands with privileged access to the array. Every filesystem and object bucket the array serves is then reachable.
Who can reach it
Network reach to the FlashBlade management interface. No valid operator credential is needed - the unintended authentication method is the way in.
What to do
Upgrade Purity//FB to the fixed release from Pure's security bulletin. Before and after, restrict the management interface to an administrative network, and review array audit logs for logins that did not come from a known admin.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.